CLOSED: Evidence that SoftEther VPN Service exe has embedded malware
Posted: Fri Sep 27, 2013 10:33 am
WARNING: Evidence that SoftEther VPN Service exe has embedded malware.
Thought I should report that the Windows Service called SoftEther VPN Client (program executable is vpnclient_x64.exe) is sending outbound messages to IP address 80.82.64.193 - a suspicious site that is blocked by Malwarebytes. These outbound messages are being sent even when the SoftEther VPN Client Manager is NOT connected to a VPNGate node - i.e., when it is inactive.
Also 80.82.64.193 (dea.anonymouse.me) is often listed on the VPNGate Hostname list in the VPN Client Manager GUI.
I asked on the Malwarebytes support forum why Malwarebytes is blocking outgoing VPN Gate IP address 80.82.64.193 (WHOIS says Host dea.anonymouse.me Country Netherlands).
They advised that this IP address was on their blocked list, because:
____________________
That IP is on a range of servers that are known to recently be participating or housing threats that can potentially harm someones computer and why the IP is blocked.
IP Address 80.82.64.193= ET-RBN Known Russian Buisness Network IP with malicious detections as of Today-9-27-2013
It would seem your software is allowing you to connect to IP's that can be malicious.
____________________
I had been running VPNGate using installer vpngate-client-2013.07.20-build-9091.127245.zip
So, I fully uninstalled/expunged the SoftEther VPN and all related VPN Gate system files, and clean reinstalled from vpngate-client-2013.09.27-build-9387.127802.zip (downloaded from http://download.vpngate.jp/common/cd.as ... 127802.zip)
However, the outbound requests to IP Address 80.82.64.193 continued as before.
This would seem to indicate that the installer package may have malware embedded in it, resident in the SoftEther VPN Service exe, and that it is ALWAYS ACTIVE when the Service is running.
Hope this makes sense or is of use.
Thought I should report that the Windows Service called SoftEther VPN Client (program executable is vpnclient_x64.exe) is sending outbound messages to IP address 80.82.64.193 - a suspicious site that is blocked by Malwarebytes. These outbound messages are being sent even when the SoftEther VPN Client Manager is NOT connected to a VPNGate node - i.e., when it is inactive.
Also 80.82.64.193 (dea.anonymouse.me) is often listed on the VPNGate Hostname list in the VPN Client Manager GUI.
I asked on the Malwarebytes support forum why Malwarebytes is blocking outgoing VPN Gate IP address 80.82.64.193 (WHOIS says Host dea.anonymouse.me Country Netherlands).
They advised that this IP address was on their blocked list, because:
____________________
That IP is on a range of servers that are known to recently be participating or housing threats that can potentially harm someones computer and why the IP is blocked.
IP Address 80.82.64.193= ET-RBN Known Russian Buisness Network IP with malicious detections as of Today-9-27-2013
It would seem your software is allowing you to connect to IP's that can be malicious.
____________________
I had been running VPNGate using installer vpngate-client-2013.07.20-build-9091.127245.zip
So, I fully uninstalled/expunged the SoftEther VPN and all related VPN Gate system files, and clean reinstalled from vpngate-client-2013.09.27-build-9387.127802.zip (downloaded from http://download.vpngate.jp/common/cd.as ... 127802.zip)
However, the outbound requests to IP Address 80.82.64.193 continued as before.
This would seem to indicate that the installer package may have malware embedded in it, resident in the SoftEther VPN Service exe, and that it is ALWAYS ACTIVE when the Service is running.
Hope this makes sense or is of use.